Файл: modules/clans/forum/add_msg.php
Строк: 70
<?php
$mem_start = memory_get_usage();
require '../../../system/func_for_game2.inc.php';
if(!isset($_GET['clan'])){
$clan=mysqli_fetch_array(mysqli_query($link,"SELECT * FROM `clans` WHERE `id`='".num($user['clan'])."'"));
if($clan['id']>0){
if(isset($_GET['r'])){$razdel=num($_GET['r']);}else{$razdel=0;}
if(isset($_GET['id'])){$id=num($_GET['id']);}else{$id=0;}
$proverka_theme = mysqli_num_rows(mysqli_query($link,"SELECT * FROM `clans_forum_theme` WHERE `id`='$id' and `id_clan`='".num($clan['id'])."' "));
if($proverka_theme!=0){
$thema = mysqli_fetch_array(mysqli_query($link,"SELECT * FROM `clans_forum_theme` WHERE `id`='$id'"));
if ($thema['status'] == 'open') {
if(!empty($_POST['text']))
{
$msg=vvod($_POST['text']);
if(mb_strlen($msg,'utf-8') > 1 and mb_strlen($msg,'utf-8') < 1500)
{if($razdel!=1){$time=time();mysqli_query($link,"UPDATE `clans_forum_theme` SET `timer`='$time' WHERE `id`='".num($thema['id'])."'");}
mysqli_query($link,"INSERT INTO `clans_forum_msg` ( `id` ,`id_theme` ,`id_add` ,`id_clan`, `msg` , `data` ,`tip` )VALUES ( '', '$id','".num($user['id'])."','".num($clan['id'])."', '$msg', '".time()."','$razdel')");
}}}}
go("/clans/forum?r=$razdel&id=$id");
}else{
go("/clans");}
}else{
$cl=num($_GET['clan']);
$clan=mysqli_fetch_array(mysqli_query($link,"SELECT * FROM `clans` WHERE `id`='$cl'"));
if($clan['id']>0){
if(isset($_GET['r'])){$razdel=num($_GET['r']);}else{$razdel=0;}
if(isset($_GET['id'])){$id=num($_GET['id']);}else{$id=0;}
$proverka_theme = mysqli_num_rows(mysqli_query($link,"SELECT * FROM `clans_forum_theme` WHERE `id`='$id' and `id_clan`='".num($clan['id'])."' "));
if($proverka_theme!=0){
$thema = mysqli_fetch_array(mysqli_query($link,"SELECT * FROM `clans_forum_theme` WHERE `id`='$id'"));
if ($thema['status'] == 'open' and $thema['razdel'] == 2) {
if(!empty($_POST['text']))
{
$msg=vvod($_POST['text']);
if(mb_strlen($msg,'utf-8') > 1 and mb_strlen($msg,'utf-8') < 1500)
{if($razdel!=1){$time=time();mysqli_query($link,"UPDATE `clans_forum_theme` SET `timer`='$time' WHERE `id`='".num($thema['id'])."'");}
mysqli_query($link,"INSERT INTO `clans_forum_msg` ( `id` ,`id_theme` ,`id_add` ,`id_clan`, `msg` , `data` ,`tip` )VALUES ( '', '$id','".num($user['id'])."','".num($clan['id'])."', '$msg', '".time()."','$razdel')");
}}}}
go("/clans/forum?r=$razdel&id=$id&clan=$cl");
}else{
go("/clans");}
}
?>